CVE-2016-10044: Google Android

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.

Affected products

  • Google Android: up to and including 7.1.1
  • Linux Linux Kernel: before 3.16.43 (fixed in 3.16.43); from 3.17, before 4.4.24 (fixed in 4.4.24); from 4.5, before 4.7.7 (fixed in 4.7.7)

Published 2017-02-07. Last modified 2026-06-17.